Description
Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized RBAC Relationship Deletion
Action: Patch Now
AI Analysis

Impact

The Yeti platform accepts DELETE requests to /api/v2/rbac/{id} without checking the caller’s permissions. Users who only have read access can therefore delete access‑control relationships, which can revoke ownership of objects and permanently lock legitimate owners out.

Affected Systems

All Yeti platform releases through version 2.11.0, identified by the cpe:2.3:a:yeti-platform:yeti, are affected. The vulnerability is present in the core Web API code as shown in earlier source versions, before the latest fix.

Risk and Exploitability

The CVSS score of 7.2 classifies this as a high‑severity vulnerability. The EPSS score is below 1 %, indicating a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by authenticating with any user account that possesses read permissions, then issuing a DELETE request to remove an RBAC relationship. Because no additional privileges or conditions are required, an attacker with minimal access can permanently alter access control.

Generated by OpenCVE AI on September 17, 2026 at 23:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Yeti to the latest release that includes the RBAC permission check.
  • If no patch is available, remove delete privileges from non‑admin users and ensure that the DELETE /api/v2/rbac/{id} endpoint requires an administrative role.
  • Restrict RBAC modification operations to users with explicit administrative authorization and monitor API activity for suspicious deletions.

Generated by OpenCVE AI on September 17, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legitimate owners out of objects.
Title Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion
First Time appeared Yeti-platform
Yeti-platform yeti
Weaknesses CWE-862
CPEs cpe:2.3:a:yeti-platform:yeti:*:*:*:*:*:*:*:*
Vendors & Products Yeti-platform
Yeti-platform yeti
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Yeti-platform Yeti
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:48:45.094Z

Reserved: 2026-09-16T19:22:54.542Z

Link: CVE-2026-92783

cve-icon Vulnrichment

Updated: 2026-09-17T13:48:39.290Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:27.433

Modified: 2026-09-23T17:17:49.237

Link: CVE-2026-92783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses